Skip to content

move verify_delegate() from Metadata to Signed #2361

Description

@jku

verify_delegate() is currently an instance method of Metadata. It could be an instance method of Signed since it does not need anything from metadata and since this would lead to cleaner code.

  • Generally code that uses tuf.repository can mostly look clean as it does not need to deal with the actual Metadata:
    root = repo.root()
    print (f"root version is {root.version}")
    
    This no longer works if one wants to verify a delegate just because of API design
  • We could add a Signed.verify_delegate() and similar code should work:
    root = repo.root()
    root.verify_delegate("targets", metadata)
    
  • nothing prevents leaving Metadata.verify_delegate() in place as a deprecated method

Activity

  1. added
    discussionDiscussions related to the design, implementation and operation of the project
    on Apr 17, 2023
  2. jku commented on Apr 17, 2023

    @jku
    MemberAuthor

    I thought I had filed this already but failed to find it -- please close if I was dumb and an issue exists already

  3. lukpueh commented on Apr 17, 2023

    @lukpueh
    Member

    I thought I had filed this already but failed to find it -- please close if I was dumb and an issue exists already

    We discussed this here: #2272 (comment), but I don't think we created an issue.

  4. jku commented on May 4, 2023

    @jku
    MemberAuthor

    I'm trying this and it looks like as a result I can also simplify Updater/TrustedMetadataSet a bit:

    we currently have accessors like TrustedMetadataSet.root which are used like consistent_snapshot = trusted_set.root.signed.consistent_snapshot
    However, verify_delegate() seems to be the only reason why these accessors are type Metadata, and not the Signed object.

  5. jku commented on Aug 22, 2023

    @jku
    MemberAuthor

    Just to document how this evolved:

    This was the original proposal:

    root = repo.root()
    root.verify_delegate("targets", metadata)
    

    that is now actually:

    root = repo.root()
    root.verify_delegate("targets", metadata.signed_bytes, metadata.signatures)
    

    So API is a bit more complicated but Root is now not dependent on knowing about Metadata: this is great for future DSSE container format work linked above

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    discussionDiscussions related to the design, implementation and operation of the project

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions